Back to Malware Drops
4f75eec50688856480316bb404ba90d33d5de43ded45066b5a3d9b3fb7cc8720
MD5480cca2893407eb1d59970c9ca8ab831
SSDEEP48:ELnZxiSbGVQmGf/LU8fGUa/U/BqxGDf/LLj/U/B0:ix5bsQmGfQQGUa8sGDfD8C
File Typetext/x-script
Size2.3 KB
Sources77
Downloads0
First SeenJul 19, 2018
Last SeenSep 18, 2018
Download sample (.zip, password: infected)
Live malware — handle only in an isolated analysis environment.
Originating Attacks
Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.
- Dropped in this session (no command captured).Jul 19, 2018, 4:32:19 AMView attack session
- Dropped in this session (no command captured).Jul 19, 2018, 4:32:19 AMView attack session
- Dropped in this session (no command captured).Jul 19, 2018, 4:32:19 AMView attack session
- Dropped in this session (no command captured).Jul 19, 2018, 4:32:19 AMView attack session
- Dropped in this session (no command captured).Jul 19, 2018, 4:32:19 AMView attack session
Indicators of Compromise
Values are defanged (e.g. hxxp://, [.]) — not live links.
domain (1)
- ddos[.]sddos[.]xyz
url (2)
- hxxp://ddos[.]sddos[.]xyz:8181/systems1
- hxxp://ddos[.]sddos[.]xyz:9960/systems